The VPN You Trusted Just Became the Threat. Your VPN is supposed to keep you safe from prying eyes and hackers. But what if it was being used to breach your defenses and spy on you?
A new threat has been discovered by cybersecurity researchers at Fortinet which targets the QuickFox VPN. QuickFox is a popular VPN application among Chinese users as it increases the speed at which Chinese-based websites and gaming services can be accessed. However, for over a year, hackers were able to modify QuickFox’s installer to smuggle malware onto users’ PCs. This malware was hidden deep within the genuine QuickFox software, making it a particularly stealthy attack which went unnoticed.
As VPNs are such a crucial part of modern cybersecurity, we’re going to take a closer look at what happened.
A Backdoor Hidden in Plain Sight
Developing a VPN is far from straightforward. Significant coding is needed to ensure that all the requirements of a VPN can be met. Consequently, a VPN is comprised of numerous and complex files. This is what allowed the hackers to strike. By tampering with a HTML file within the QuickFox installer, the attackers were able to initiate the download of a malicious JavaScript file. This file originated from a malicious website, cleverly designed to mimic the official QuickFox one.
The code – which was ridiculously simple at just two lines long – started its campaign by verifying whether the affected PC was a worthwhile target. If it detected that the PC was running Steam – a popular gaming platform – it aborted the attack immediately. Clearly, the attackers weren’t after casual gamers. Instead, they appeared to be targeting machines used by developers. If the malware could verify that tools such as Visual Studio Code and cryptocurrency wallets were present, the attack was on.
The next step in the attack was to use the legitimate Windows Azure Compute utility to install further malicious code. As Windows Azure Compute is a trusted application, no alarms would be raised and the installation would go unchallenged. Therefore, the malware was able to remain in the background and harvest data about the victim such as network details, credentials, and operating system information. As the campaign progressed, the attackers were able to install further malware to strengthen their attack.
How to Keep Yourself Protected
Mustang Panda – a state-sponsored Chinese hacking group – are believed to be behind this campaign. While they may not be targeting you, the mechanics of this attack could easily be used to target your organization. But you don’t have to become a victim. Instead, you can stay safe with our three top tips:
- Always Update Immediately: the best way to protect your PC is by ensuring that all your software is up to date. This means installing the latest version or updating it with software patches.
- Be Cautious of Lesser-Known VPNs: larger VPN services tend to have a strong security backing, and this is supported by independent audits carried out by tech experts. Lesser-known VPNs, however, don’t always have this accreditation. So, while they may be cheaper, they may not be as secure.
- Look Out for Unusual Activity on Your PC: unexpected background processes, random mouse cursor movement, and slow performance could indicate that your PC is being controlled remotely. If you do encounter anything out of the ordinary, always report it to an IT professional.
For more ways to secure and optimize your business technology, contact your local IT professionals.




